Hardware wallet manufacturer Trezor has issued an urgent warning about a surge in phishing attempts that exploit the recent Coldcard security incident. The company emphasized that users must never share their recovery seeds, as legitimate operations never request such sensitive information.
In a post on X, Trezor stated that recovery seeds should only be entered directly on a Trezor device during wallet restoration and that any communication asking for them is a red flag. Scammers are leveraging the Coldcard breach to trick users into revealing seed phrases through fake migration instructions or urgent warnings sent via email, SMS, or phone calls.
The Coldcard incident has led to significant losses. According to Galaxy Research, approximately 1,596 BTC (over $100 million) has been stolen from more than 7,300 addresses, with the total potentially rising to 2,055 BTC (near $130 million). At least 15 separate attackers are exploiting a firmware flaw dating back to March 2021 that made private keys guessable.
Security firm Proofpoint documented a phishing campaign targeting Coldcard users. Emails from a spoofed Coldcard address invite recipients to complete a “coordinated hardware audit,” linking to a cloned website that installs ScreenConnect, a remote-access tool. The fake site even features a live customer service chat where a real person walks victims through the installation, making the social engineering highly effective.
Trezor clarified that it was not affected by the Coldcard exploit, but the company is proactively warning users to remain vigilant. Foundation, another hardware wallet maker, also reported phishing emails impersonating its brand and pushing malicious downloads. Both firms reiterate they will never ask for recovery phrases or instruct users to install software to secure a wallet.
The campaign preys on the fear generated by the ongoing thefts, and Galaxy Research warns that the exploit is still active, urging Coldcard users to move funds to a fresh seed or a custodian. The phishing threat is expected to persist as long as the original incident remains unresolved.